CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4368  CVE-2001-1568  Candidate  CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.  Assigned (20050714)  None (candidate not yet proposed)    View
69904  CVE-2014-2609  Candidate  The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.  Assigned (20140324)  None (candidate not yet proposed)    View
4624  CVE-2002-0232  Candidate  Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
70160  CVE-2014-2865  Candidate  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a "" character, as demonstrated by using this character within a pathname on the drive containing the web root directory of a ColdFusion installation.  Assigned (20140415)  None (candidate not yet proposed)    View
4880  CVE-2002-0488  Entry  Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.        View

Page 1296 of 20943, showing 5 records out of 104715 total, starting on record 6476, ending on 6480

Actions